PT-2024-21857 · Samsung · Exynos 1380+4
Published
2024-06-05
·
Updated
2024-08-20
·
CVE-2024-27370
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Samsung Mobile Processor Exynos 980
Samsung Mobile Processor Exynos 850
Samsung Mobile Processor Exynos 1280
Samsung Mobile Processor Exynos 1380
Samsung Mobile Processor Exynos 1330
Description
An issue was discovered in the function
slsi nan config get nl params(), where there is no input validation check on hal req->num config discovery attr coming from userspace, which can lead to a heap overwrite.Recommendations
For Samsung Mobile Processor Exynos 980, update to a version that includes input validation for
hal req->num config discovery attr.
For Samsung Mobile Processor Exynos 850, update to a version that includes input validation for hal req->num config discovery attr.
For Samsung Mobile Processor Exynos 1280, update to a version that includes input validation for hal req->num config discovery attr.
For Samsung Mobile Processor Exynos 1380, update to a version that includes input validation for hal req->num config discovery attr.
For Samsung Mobile Processor Exynos 1330, update to a version that includes input validation for hal req->num config discovery attr.
As a temporary workaround, consider disabling the slsi nan config get nl params() function until a patch is available.Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exynos 1280
Exynos 1330
Exynos 1380
Exynos 850
Exynos 980